Public exploitation
Exploit catalog
Every public exploit we catalog, in one index. Search by CVE, exploit name or technology — and see, right beside it, what the flaw is actually worth: severity, exploitation probability, and whether it’s already under attack.
78,958cataloged exploits
36,206CVEs with public exploitation
24,695lab-tested
AllExploit-DB 24,460Referência 22,832GitHub PoC 14,991VulnCheck XDB 8,829Nuclei 4,357Metasploit 3,489✓ verified onlyrecentpopularrisk
78,325 exploits
GitHub PoC★ 4
weblogic CVE-2021-2109批量验证poc
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
63RISK
open ↗GitHub PoC★ 6
CVE-2020-9496和CVE-2021-26295利用dnslog批量验证漏洞poc及exp
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open ↗GitHub PoC★ 236
Exploit to SYSTEM for CVE-2021-21551
Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privile
100RISK
open ↗VulnCheck XDB
initial-access
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open ↗VulnCheck XDB
client-side
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗GitHub PoC★ 12
exiftool arbitrary code execution vulnerability
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗VulnCheck XDB
initial-access
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open ↗GitHub PoC★ 1
0xm4ud/Cacti-CVE-2020-8813
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RISK
open ↗GitHub PoC★ 96
Python exploit for the CVE-2021-22204 vulnerability in Exiftool
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗Metasploit500
Linux eBPF ALU32 32-bit Invalid Bounds Tracking LPE
Linux kernel eBPF bitwise ops ALU32 bounds tracking
41RISK
open ↗VulnCheck XDB
initial-access
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used,
50RISK
open ↗Metasploit300
Windows IIS HTTP Protocol Stack DOS
HTTP Protocol Stack Remote Code Execution Vulnerability
100RISK
open ↗Metasploit600
Microsoft SharePoint Unsafe Control and ViewState RCE
Microsoft SharePoint Remote Code Execution Vulnerability
48RISK
open ↗VulnCheck XDB
client-side
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code exec
100RISK
open ↗GitHub PoC★ 3
POC Exploit written in Ruby
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RISK
open ↗GitHub PoC★ 3
Exploit for Node-jose < 0.11.0 written in Ruby
A vulnerability in the Cisco node-jose open source library before 0.11.0 could allow an unauthenticated, remote attacker
35RISK
open ↗GitHub PoC
fu2x2000/CVE-2017-17058-woo_exploit
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RISK
open ↗Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Metasploit600
Apache 2.4.49/2.4.50 Traversal RCE
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RISK
open ↗Exploit-DB
Microweber CMS 1.1.20 - Remote Code Execution (Authenticated)
A directory traversal issue in the Utils/Unzip module in Microweber through 1.1.20 allows an authenticated attacker to g
28RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗GitHub PoC★ 3
Check YouTube - https://youtu.be/O0ZnLXRY5Wo
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗Metasploit300
Apache 2.4.49/2.4.50 Traversal RCE scanner
Path Traversal and Remote Code Execution in Apache HTTP Server 2.4.49 and 2.4.50 (incomplete fix of CVE-2021-41773)
100RISK
open ↗VulnCheck XDB
initial-access
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Console). Supported versions
100RISK
open ↗VulnCheck XDB
initial-access
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗GitHub PoC★ 6
CVE-2017-7494 python exploit
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allo
100RISK
open ↗GitHub PoC★ 3
CVE-2019-2215
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗VulnCheck XDB
initial-access
XML-RPC request are vulnerable to unsafe deserialization and Cross-Site Scripting issues in Apache OFBiz 17.12.03
60RISK
open ↗VulnCheck XDB
local
A use-after-free in binder.c allows an elevation of privilege from an application to the Linux Kernel. No user interacti
100RISK
open ↗We index only the public link to the proof of concept — we never host or redistribute exploitation code. Sources: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit and VulnCheck XDB. A public PoC existing does not mean the flaw is exploitable in your environment.